Privacy Policy
Last updated: June 1, 2026
This privacy policy explains how the Efsun (Esrar-ı Osmani) mobile application (the "App") collects, uses, stores and protects your personal data. By using the App you are deemed to accept this policy.
1. Data We Collect
1.1 Account Information
- Email address (Google / Apple sign-in or email registration)
- Display name and profile photo (automatically from your social account)
- System-assigned unique user identifier
1.2 Reading Inputs
- Name, date of birth, place of birth, mother's name (for Yıldızname, Ebced and similar features)
- Intention, question, or any free text you provide
- Photos you upload for image-based readings (coffee, palm, aura, evil eye — not stored permanently, only used for the current reading)
1.3 Device and Usage Data
- Device fingerprint (cryptographic digest — used to prevent onboarding-gift abuse)
- Anonymous push-notification token (so you can receive notifications)
- App version, operating system and language preference
- Anonymous usage analytics (screen views, feature usage)
1.4 Purchase Information
- Purchase records made via Google Play / App Store (transaction ID, product, amount)
- Credit-card or banking details are never collected or stored — all payments go through Google/Apple.
2. How We Use Data
- To generate readings: Your inputs are processed anonymously with our contracted AI service provider to produce personalised interpretations.
- Account and credit management: To track your balance, purchases, and reading history.
- Notifications: To send the notifications you have opted in to (daily Esma, streak reminders, cosmic event announcements, etc.).
- Abuse protection: Device fingerprint prevents creating multiple accounts on the same device to receive multiple welcome gifts.
- Improvement: Anonymous usage data helps us understand how features perform and improve the App.
3. Image Retention Policy
For image-based readings (coffee fortune, palm, aura, evil eye, face/physiognomy) any photo you upload is:
- Sent only to our AI service provider for the current reading.
- Not stored permanently in our databases or servers.
- Discarded from memory once the reading is complete.
- If submitted to Expert Mode it is kept only for the limited duration of the scholar's review, then deleted.
3.A Access via the Claude.ai MCP Connector
Efsun provides an MCP (Model Context Protocol) Connector for Anthropic Claude.ai. When you add the connector to Claude and bind it to your Efsun account:
- Your credentials (email + password) are verified only at the Efsun OAuth server; Claude.ai and Anthropic never see your password.
- OAuth 2.0 + PKCE is used; Claude.ai calls the connector with a short-lived (1-hour) access token.
- Inputs you give Claude in tool calls (name, dream text, photos, etc.) are routed through Anthropic's infrastructure and Efsun's MCP server to our AI provider; the same rules as the mobile app apply.
- Shared balance: Connector credits are shared with the mobile app — the same user is authenticated on both channels.
- You can revoke the connection at any time from Claude.ai's connector settings; the refresh token stored on our server is then invalidated.
- All connector calls are recorded with a
source: "mcp"tag in our audit logs (for mobile vs. MCP attribution).
See the Efsun MCP Connector documentation for details.
4. Third-Party Service Providers
We work with industry-standard external providers to operate the App. Your data is processed under each provider's KVKK / GDPR-compliant privacy policy:
- Cloud infrastructure provider: User authentication, database, server functions, anonymous analytics, error tracking and notifications.
- AI service provider: Generates the reading content. Your inputs are processed anonymously and not persisted.
- Anthropic (if you use the Claude.ai MCP Connector): If you bind the connector through Claude.ai, the messaging flow passes through Anthropic's infrastructure and Anthropic's own privacy policy applies.
- App-store payment infrastructure: All payments happen inside Google Play Store and Apple App Store, under their own secure systems.
- Advertising network partners: Only for free users, untargeted ad delivery (no ads for premium users).
For the current list of providers you may request it from our contact form.
5. Data Retention
- Account information: until the account is deleted.
- Reading history: stored in your account, individually deletable any time.
- Images: deleted immediately (as described above).
- Audit / purchase logs: retained for 5 years to comply with legal requirements.
- Anonymous analytics data: 14 months (industry standard).
6. Your Rights (KVKK & GDPR)
Under applicable law you have the right to:
- Learn what data we keep about you
- Request correction or update of your data
- Delete your account and all your data ("Delete my account" button inside the App)
- Data portability (request a copy of your data)
- Object to processing
To exercise these rights please use the contact page or write to info@anka.istanbul.
7. Children's Privacy
Our App is not intended for children under 13. We do not knowingly collect data from anyone under 13. If you believe your child has shared information, please contact us; we will delete the data promptly.
8. Data Security
We use HTTPS / TLS for transmission, encrypted storage in the cloud, server-side prompt assembly, audit logs and strict admin access controls. Despite all efforts, no system is 100% secure; please notify us at any sign of an incident.
9. Changes
This policy may be updated over time. The "Last updated" date at the top reflects the latest change. Substantive changes are announced via in-app notification.
10. Contact
For any questions about this policy: info@anka.istanbul
Anka Software, Istanbul / Türkiye
© 2026 Anka Software · Efsun (Esrar-ı Osmani)